온-프레미스 또는 공동 배치 환경에서 Azure 데이터 센터와 인프라 간에 프라이빗 연결을 제공하는 Azure 서비스입니다.
Hi 이재옥,
Thanks for reaching out in Microsoft Q&A forum,
Is it possible to link a single ExpressRoute circuit to both the standard VNet Gateway and the Virtual WAN Hub Gateways simultaneously?
Yes, a single ExpressRoute circuit (Standard SKU) CAN connect simultaneously to both:
- Your existing traditional ExpressRoute Gateway (
Microsoft.Network/virtualNetworkGateways) in the Hub VNet, AND - ExpressRoute Gateways (
Microsoft.Network/expressRouteGateways) in your Virtual WAN hubs (vHub 1 & vHub 2).
This hybrid coexistence is officially supported and recommended for low-downtime, phased migrations.
Microsoft explicitly documents this scenario in their migration guidance:
"Both the original customer-managed hub virtual network and the new Virtual WAN Hub are both connected to the same ExpressRoute circuit. This allows spokes in both environments to communicate during staged migration." Migrate from hub-spoke topology to Azure Virtual WAN
How It Works:
The key principle is that both gateway types traditional VNet ExpressRoute Gateway and Virtual WAN ExpressRoute Gateway.
Connect through the same private peering on the Microsoft Enterprise Edge (MSEE) devices for a given ExpressRoute circuit.
Core Connectivity Theory:
- Single Circuit, Multiple Authorization Keys: Generate separate authorization keys for each gateway-circuit connection. Each gateway redeems its own key independently.
- Shared MSEE Peering: Both gateways establish BGP sessions to the identical MSEE private peering endpoint.
- Bidirectional Traffic Enablement:
- Traditional gateway: Enable "Allow traffic from remote Virtual WAN networks"
- vWAN gateways: Enable "Allow traffic from non-Virtual WAN networks"
Migration Flow:
Phase 1: vWAN hubs deployed with ER gateways
Phase 2: Existing ER circuit connects to vWAN (traditional gateway stays linked)
Phase 3: Hybrid traffic validated (spoke ↔ vWAN spoke via shared circuit)
Phase 4: Spokes migrate to vWAN progressively
Phase 5: Traditional gateway decommissioned
Architectural Concerns:
No Control Plane Conflicts: Both gateways operate under Microsoft's unified ExpressRoute service fabric. The distinction is in management plane (customer-managed VNet vs. vWAN-managed hubs), not data plane connectivity.
Standard SKU Fully Supported: Circuit SKU limits apply per peering location, not gateway type combinations.
Official Documentation:
- Migrate from hub-spoke to Azure Virtual WAN < Primary source (Steps 3-4 explicitly describe shared-circuit coexistence with diagrams)
- About ExpressRoute in Virtual WAN (Multiple connections, authorization keys)
- ExpressRoute Virtual Network Gateways (VNet <-> vWAN traffic settings)
Kindly let us know if the above helps or you need further assistance on this issue.
Please do not forget to
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.